Circuit Wire — a daily news update from the Circuit.

Cisco has confirmed that attackers are exploiting a critical flaw in Catalyst SD-WAN Manager, formerly known as vManage, tracked as CVE-2026-76504, that lets an unauthenticated remote user gain administrator access, BleepingComputer reported on September 30. Cisco's security team detected the exploitation in September.

The bug sits in how the product's API session management handles URI encoding. Attackers send crafted HTTP requests that use the encoded character "%6a" in place of a "j," which slips past the authentication filters on certain API endpoints and grants full privileges. The flaw carries a severity score of 9.8 out of 10, SecurityWeek reported.

Every Catalyst SD-WAN Manager deployment is affected, whatever its configuration, and no workaround exists. BleepingComputer noted that the required patch level differs by release branch, from 20.9.10.1 through 26.2.1. Fixed releases include 26.2.1, 26.1.2.1, 20.18.4.1, 20.15.6.1, 20.12.8.2 and 20.9.10.1. SecurityWeek advises hunting for POST requests to URL-encoded variants of the /j_security_check path to spot attempts.

The US Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog on September 30. Federal agencies were given three days to patch, according to SecurityWeek. Security Affairs reported that Cisco found the issue during a customer support investigation.

It is not the first exploited flaw in the product line this year. In May, CyberScoop reported that a separate Cisco SD-WAN authentication bypass, CVE-2026-20182, was being exploited by a threat group tracked as UAT-8616. That flaw let attackers pose as a trusted router to a controller and gain administrative access. Rapid7 discovered that flaw on March 9. Cisco learned of limited exploitation in early May, released a patch on May 15, and CISA added it to the exploited-vulnerabilities catalog the same day. CyberScoop said at least 10 other threat groups were also chaining vulnerabilities in the product line.

The disclosure follows the two Citrix NetScaler zero-days exploited in global attacks that we covered earlier this week.

Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.

Spotted something we should cover? Send tips and feedback via circuit-magazine.com.